LIVE · cybersecurity feed
Live wire
breach

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]

zeroday.news · 1d ago

A Chinese-speaking threat actor has been observed using the DeepSeek artificial intelligence model in conjunction with the open-source Hermes Agent to conduct autonomous cyberattacks against internet-exposed servers. This activity, attributed to an individual operating under the aliases "knaithe" and "KnYuan," was uncovered by researchers at Palo Alto Networks' Unit 42.

The discovery was made after the Hermes Agent inadvertently created a web server from its home directory, exposing the attacker's operational environment. This exposed data included API keys, exploit scripts, target lists, shell history, and logs detailing the AI-driven attacks. While the autonomous attacks observed by Unit 42 did not result in successful compromises of the targeted systems, the campaign demonstrates a functional, end-to-end autonomous offensive capability.

The threat actor utilized DeepSeek as the reasoning engine for the Hermes Agent, an AI framework designed to interact with operating system terminals, execute commands, and connect to the internet. The agent was configured with a "Yolo" mode, allowing it to operate and execute commands, including potentially risky ones, without requiring prior operator permission. Instructions were provided via a Telegram channel, and the agent integrated custom offensive-security skills with the FOFA internet asset search engine.

In a session from May 2026, the operator reportedly provided only an initial task, after which the agent proceeded autonomously. The agent initially targeted Langflow servers vulnerable to CVE-2026-33017. It downloaded a public proof-of-concept exploit, identified 84 exposed instances via FOFA, and scanned them for vulnerable configurations. After determining these targets were not exploitable, the agent searched for other vulnerabilities.

DeepSeek then analyzed multiple public exploit repositories before selecting the n8n workflow automation platform as a new target, identifying over 647,000 exposed instances through FOFA. The agent downloaded an exploit chaining CVE-2026-21858 and CVE-2025-68613, identified servers running vulnerable versions, and checked for unauthenticated file-upload forms necessary for the attack. However, the discovered forms required authentication, leading to the autonomous attempts failing to compromise any targets.

Unit 42 highlighted the significance of this campaign, noting that the AI agent independently researched vulnerabilities, determined optimal targets, downloaded exploit code, and attempted exploitation within minutes—a process that would typically take many hours of manual effort. This autonomous process of target identification, sampling, and scope narrowing executed hundreds of hours of manual analysis in mere minutes, while also managing its own compute resources.

Beyond the AI-driven attacks, the threat actor also conducted manual attacks against over 460 systems. These manual efforts targeted vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, and Windows IKE VPN, among other products. Unit 42 confirmed three successful compromises targeting the Citrix NetScaler vulnerability CVE-2026-3055, where the actor extracted memory and searched for authentication cookies to hijack sessions. While other AI coding platforms like Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI's Codex were configured, they were not frequently used.

This exposed AI campaign follows a previous incident involving poorly secured Hermes infrastructure, which revealed details about an alleged cyberattack against Thailand's Ministry of Finance. In that earlier event, open web directories containing exploit tools, web shells, credentials, compiled payloads, and Hermes activity logs were discovered. Those logs showed Hermes operating in "YOLO" mode to automate post-exploitation activities, including searching for privilege escalation opportunities, enumerating services, inspecting containers, traversing filesystems, and cataloging documents on Ministry of Finance systems. However, the earlier incident did not demonstrate Hermes independently selecting targets or determining compromise methods; a human operator supplied the target, objectives, and attack tools, with Hermes automating routine activities after initial access was apparently obtained.

breachvulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.